Archer — “Archer launches Archer Evolv AI Compliance, bringing runtime guardrails to AI governance” (15 September 2026)

Tag: S-2026-09-15-archer-evolv-ai-compliance Type: article (vendor press release on archerirm.com, published 15 Sep 2026 during Archer Summit; fetched in full) Author(s): Team Archer (quote: Kayvan Alikhani, Chief Product & Technology Officer) Date of source: 2026-09-15 Date ingested: 2026-09-16 Authority weight: medium — dated product-launch primary from a self-interested vendor with a specific, testable architecture (Bedrock Guardrails, IAM role scope, Observe/Advise/Enforce modes); no customer, regulator or independent test cited; obligation mappings named are privacy/security content rules, not AI-specific standards Raw file: /_raw_sources/S-2026-09-15-archer-evolv-ai-compliance.md

What it claims

Archer, a GRC platform incumbent, launched Archer Evolv AI Compliance on 15 Sep 2026. The product converts “the regulations and policies that already govern an enterprise into policy as code”: approved Amazon Bedrock Guardrails deployed natively inside the customer’s own AWS account and enforced before a model responds, for prompts from employees or agents. “Every control traces back to the obligation that required it, and every violation is recorded in the GRC system of record.”

The release frames the gap as intent, not identity: “IAM governs identity. Runtime guardrails govern intent.” It positions the product as the missing link between the governance repository and the guardrail — “much of the market delivers the repository or the guardrail, rarely the connection between them.”

The mechanism is a five-step loop: Listen (regulations and policies become tracked controls, drawing on “22 million regulatory documents” version-tracked by legal experts); Decide (controls become draft Bedrock Guardrails, “deployed only once a named owner approves them”); Act (every prompt checked before inference; violations blocked and logged); Assure (guardrails “tested on a set cycle against the approved control”, risk scored continuously, “drift or tampering is flagged”); Learn (findings routed to Archer issue management and tracked to closure). No proxy sits in the inference path; non-Bedrock models can use the Bedrock Apply Guardrail API. “Source, obligation, control, guardrail and violation event form one audit trail a customer can hand to an examiner on demand.”

Guardrails cover two obligation classes: organisational (secrets, source code, confidential business information, customer-defined usage rules) and regulatory (personal data under GDPR/CCPA/state privacy law; PHI under HIPAA; cardholder data under PCI DSS; export-controlled, securities and biometric data).

Data boundary: Archer connects via one scoped least-privilege IAM role and reads guardrail configuration and events only; prompt content, responses, documents, embeddings, PII, weights and training data “never reach Archer”; enforcement continues locally if connectivity drops. Rollout is dial-based — Observe (log what would be blocked), Advise (route finding to named owner), Enforce (block) — with approval required to move up and per-version rollback. “The exam question has changed from ‘show us your policy’ to ‘show us the control.‘” Available immediately, direct and via AWS Marketplace.

Notable quotes

  • “IAM governs identity. Runtime guardrails govern intent.” (para 5)
  • “Source, obligation, control, guardrail and violation event form one audit trail a customer can hand to an examiner on demand.” (section “Prevent the violation…“)
  • “The exam question has changed from ‘show us your policy’ to ‘show us the control.‘” (section “What stays inside…“)
  • “A guardrail is only as good as the obligation behind it.” — Kayvan Alikhani, CPTO

What’s speculative vs. asserted

Asserted (reliable as event facts): launch date; product name; AWS Marketplace availability; Bedrock Guardrails as the enforcement mechanism; the three enforcement modes.

Vendor-asserted / unverified: obligation-to-guardrail traceability in practice; “tested on a set cycle”; drift/tampering detection; the data-boundary claim (“never reach Archer”); “examiner on demand” audit trail; “492 purpose-built models”; “22 million regulatory documents”; “37 of the top 50 global banks”.

Not stated (gaps): any named customer; any AI-specific standard or regulation — EU AI Act, ISO/IEC 42001, NIST AI RMF, SS1/23, SR 11-7 and DORA are absent; how guardrail test cycles are evidenced; whether the audit trail is exportable/immutable; anything beyond AWS (Azure/GCP/on-prem models are covered only via the Apply Guardrail API, mechanism undescribed); pricing.

Vault inference (not a source claim): the obligation→control→runtime-enforcement→violation-evidence chain is structurally what EU AI Act Art. 9 (risk management), Art. 12 (logging), Art. 17 (QMS) and ISO/IEC 42001 control-traceability ask for, and the “show us the control” framing maps to SS1/23 / SR 11-7 ongoing-monitoring evidence — but the product’s stated scope is content-level data-protection guardrails, not model-risk controls.

Topics this feeds

  • AI Governance Platforms — a GRC incumbent supplying the “connection between repository and guardrail” (obligation-traced runtime enforcement on a hyperscaler’s native guardrail), extending the build-time vs run-time governance theme; answers the 10 Sep open question about whether Archer shipped a Summit-week product.
  • Archer — company page created from this and the 14 Sep release (three Archer sources now in vault).

Open questions raised

  • Are the “regulatory obligations” mappings (GDPR, HIPAA, PCI DSS, etc.) shipped as maintained content packs, and does Archer intend to add EU AI Act / ISO 42001 control mappings — or is this a data-protection guardrail product wearing an “AI governance” label?
  • Can a bank’s second line or validator rely on Archer’s “tested on a set cycle” guardrail assurance, or does SS1/23-style independent testing of the guardrail itself remain the firm’s own obligation?
  • Is the “audit trail a customer can hand to an examiner” an immutable, exportable record, and where does it sit relative to AWS’s own AgentCore/Bedrock logs and the firm’s GRC evidence store?
  • Does the AWS-only architecture create DORA ICT-concentration exposure for firms whose model estate spans Azure/GCP?